Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

DOS issue removed in UI, SAP security note 1500307

SAP Note 1500307

SAP security note 1500307, “DOS Issue Removed in UI.” Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A potential Denial of Service (DoS) vulnerability exists in MVC within SRM. A malicious user can exploit MVC to render it unavailable, potentially affecting the resources used to serve MVC, leading to a system-wide outage.

Solution

Import the corresponding support package or implement the attached advanced correction manually to address the vulnerability.

Reason and prerequisites

Infinite Loop: A malicious user can trigger a condition causing the process to enter an infinite loop, consuming all available processing time and rendering the machine unresponsive until manually terminated.

Resource Exhaustion: An attacker can send specially crafted requests that consume excessive system resources, preventing other processes from allocating new resources and causing a DoS condition.

Affected components

  • SRM 7.0
  • SRM 7.01 SP01
  • SRM 7.01 SP02

Full note on SAP: SAP Support Launchpad note 1500307

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More